Slashdot Mirror


OpenBSD Foundation Announced

OpenBDSfan writes "KernelTrap is reporting on the creation of the OpenBSD Foundation, a Canadian not-for-profit corporation intended to support OpenBSD and related projects, including OpenSSH, OpenBGPD, OpenNTPD, and OpenCVS. The announcement explains, "the OpenBSD Foundation will initially concentrate on facilitating larger donations of equipment, funds, documentation and resources. Small scale donations should continue to be submitted through the existing mechanisms.""

3 of 151 comments (clear)

  1. Re:OpenCVS? by Corporate+Troll · · Score: 4, Insightful

    Complex == insecure to them. Which, to me, implies that secure == poverty.

    No, you have your negation wrong.... If Complex == Insecure then !Complex = !Insecure, and thus Simple = Secure. The funny thing is: you cannot argue with that: simple is easier to audit and thus easier to audit. It really is that simple (Dah-dum!). Simple doesn't equate poverty, or a Lotus Elise is a poor-mans-car. (Having no radio, AC, etc...) Sorry for the "bad car analogy"(tm).

    You also forget the target demographic for OpenBSD: this is not for your Desktop, nor even for your high-load server. You can use it for that, but the niche in which it lives is firewall, NAT, transparent bridging. Places where security matters more than anything else. Sure, a bit more complex to set up, you need to work more, but this is not your moms OS.

  2. Re:OpenCVS? by Noryungi · · Score: 4, Insightful

    Just read up a little bit about OpenBSD, and you'll notice they are not afraid of complexity. Examples that come to mind are pf, OpenBGPD, W^X, etc.

    Besides, choosing a stable and secure algorithm is not a bad idea. See this post for a valid example.

    Finally, I can't help but notice that Subversion is available as an OpenBSD package, so quit your yakking already.

    Sheesh, anti-OpenBSD trolls these days.

    --
    The right to offend is far more important than the right not to be offended. (Rowan Atkinson)
  3. Re:OpenCVS? by Noryungi · · Score: 5, Insightful

    the main source of theo thinking SVN isn't secure, is because that control freak didn't write it himself. which is ironic because openssl and openssh are 2 packages responsible for huge security holes over the years, both of which are his babies.

    Except, of course, you have no fscking idea what you are talking about, since OpenSSL is not developed, or related to, OpenBSD and Theo de Raadt in any way.

    As far as OpenSSH security holes are concerned, please excuse me while I laugh. Most of these vulnerabilities are either denial of service, or someone who messed up with their OpenSSH implementation. A lot of people think they can improve on a perfectly good product by adding security holes in it.

    As far as OpenCVS is concerned, they explain their rationale quite clearly:

    The OpenCVS project was started after discussions regarding the latest GNU CVS vulnerabilities that came out. Although CVS is widely used, its development has been mostly stagnant in the last years and many security issues have popped up, both in the implementation and in the mechanisms.

    Now, let me ask you: what part of "development has been mostly stagnant in the last years and many security issues have popped up" don't you understand?

    Allow me to finish by adding this: read up a little bit before you start trolling. But that would be a waste of a perfectly good troll, right? Sheesh. Go back under your bridge, little troll.
    --
    The right to offend is far more important than the right not to be offended. (Rowan Atkinson)